## Summary epic r04 - begin refactor ## Change Type - [x] Cowork feature - [ ] Bug fix - [ ] Core AI contribution - [ ] Test / hardening - [ ] Performance - [ ] Documentation ## Related Work Cowork Task: Core Repo: http://34.143.229.138/gitea-admin/fsg-ai-core-assets Core AI Issue: Core Task: Related PR: ## Scope What is intentionally included? What is intentionally NOT included? ## Validation - [ ] Unit tests - [ ] Integration tests - [ ] Manual verification - [ ] Regression check Commands / evidence: ## Security Impact Permission / credential / network / customer data impact: ## Compatibility - [ ] No breaking change - [ ] Breaking change documented ## Reviewer Notes Anything Cowork reviewers should pay attention to. --------- Co-authored-by: Anh Tran Nguyen Minh <anhtnm1@fpt.com> Co-authored-by: Huong Le Thi Thien <huongltt35@fpt.com> Co-authored-by: Nam Pham Dinh Thanh <nampdt@fpt.com> Co-authored-by: Vu Dam Tuan <vudt15@fpt.com> Co-authored-by: Hiep Ha Van <hiephv3@fpt.com> Co-authored-by: Lam Hoang Van <lamhv7@fpt.com> Reviewed-on: #7 Co-authored-by: Duy Le Huu <duylh19@fpt.com>
This commit was merged in pull request #7.
This commit is contained in:
@@ -21,6 +21,12 @@ logger = logging.getLogger("cowork_local.security.audit")
|
||||
|
||||
@dataclass
|
||||
class AuditEntry:
|
||||
"""Một dòng nhật ký kiểm toán, đủ trường để dựng lại bối cảnh sau này.
|
||||
|
||||
Cố ý KHÔNG lưu nguyên văn lệnh: chỉ giữ ``command_hash`` (SHA-256, 16
|
||||
ký tự đầu) để đối chiếu hai lần chạy có giống nhau không, mà không đưa
|
||||
nội dung nhạy cảm vào file log.
|
||||
"""
|
||||
timestamp: str = ""
|
||||
user: str = ""
|
||||
project: str = ""
|
||||
@@ -38,6 +44,11 @@ class AuditEntry:
|
||||
approval_status: str = "" # auto, approved, rejected
|
||||
|
||||
def __post_init__(self):
|
||||
"""Điền mốc thời gian và mã băm lệnh nếu bên gọi chưa đặt.
|
||||
|
||||
Mã băm thay cho nội dung lệnh gốc: nhật ký cần truy được về sau nhưng không
|
||||
nên chứa nguyên văn thứ đã chạy.
|
||||
"""
|
||||
if not self.timestamp:
|
||||
self.timestamp = datetime.now(timezone.utc).isoformat()
|
||||
if not self.command_hash and self.action_type:
|
||||
@@ -47,6 +58,7 @@ class AuditEntry:
|
||||
|
||||
|
||||
def _audit_dir() -> Path:
|
||||
"""Thư mục chứa nhật ký kiểm toán. Import muộn để tránh vòng import với ``config``."""
|
||||
from ..config import CONFIG_DIR
|
||||
return CONFIG_DIR / "audit"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user